scrapfly-browser

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s core purpose and official Scrapfly data flow are coherent, but the optional BYOP connector materially expands risk. It instructs users to curl|sh a same-org but unverifiable binary and pass API-linked credentials through it, which triggers a high security-risk classification even without clear malicious intent.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Sep 16, 2026, 04:06 AM
Package URL
pkg:socket/skills-sh/scrapfly%2Fskills%2Fscrapfly-browser%2F@cb920293bc26b23fc688448b3cb295e6477a49a625a0af61b2133133ec72f975
Security Audit — socket — scrapfly-browser